1   /**
2    * Copyright (c) 2000-2009 Liferay, Inc. All rights reserved.
3    *
4    * Permission is hereby granted, free of charge, to any person obtaining a copy
5    * of this software and associated documentation files (the "Software"), to deal
6    * in the Software without restriction, including without limitation the rights
7    * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
8    * copies of the Software, and to permit persons to whom the Software is
9    * furnished to do so, subject to the following conditions:
10   *
11   * The above copyright notice and this permission notice shall be included in
12   * all copies or substantial portions of the Software.
13   *
14   * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15   * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16   * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17   * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18   * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19   * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20   * SOFTWARE.
21   */
22  
23  package com.liferay.portal.servlet.filters.sso.ntlm;
24  
25  import com.liferay.portal.kernel.log.Log;
26  import com.liferay.portal.kernel.log.LogFactoryUtil;
27  import com.liferay.portal.kernel.servlet.BrowserSnifferUtil;
28  import com.liferay.portal.kernel.servlet.HttpHeaders;
29  import com.liferay.portal.kernel.servlet.HttpMethods;
30  import com.liferay.portal.kernel.util.GetterUtil;
31  import com.liferay.portal.security.ldap.PortalLDAPUtil;
32  import com.liferay.portal.servlet.filters.BasePortalFilter;
33  import com.liferay.portal.util.PortalInstances;
34  
35  import javax.servlet.FilterChain;
36  import javax.servlet.http.HttpServletRequest;
37  import javax.servlet.http.HttpServletResponse;
38  
39  import jcifs.ntlmssp.Type1Message;
40  import jcifs.ntlmssp.Type2Message;
41  
42  import jcifs.util.Base64;
43  
44  /**
45   * <a href="NtlmPostFilter.java.html"><b><i>View Source</i></b></a>
46   *
47   * @author Brian Wing Shun Chan
48   */
49  public class NtlmPostFilter extends BasePortalFilter {
50  
51      protected Log getLog() {
52          return _log;
53      }
54  
55      protected void processFilter(
56              HttpServletRequest request, HttpServletResponse response,
57              FilterChain filterChain)
58          throws Exception {
59  
60          long companyId = PortalInstances.getCompanyId(request);
61  
62          if (PortalLDAPUtil.isNtlmEnabled(companyId) &&
63              BrowserSnifferUtil.isIe(request) &&
64              request.getMethod().equals(HttpMethods.POST)) {
65  
66              String authorization = GetterUtil.getString(
67                  request.getHeader(HttpHeaders.AUTHORIZATION));
68  
69              if (authorization.startsWith("NTLM ")) {
70                  byte[] src = Base64.decode(authorization.substring(5));
71  
72                  if (src[8] == 1) {
73                      Type1Message type1 = new Type1Message(src);
74                      Type2Message type2 = new Type2Message(
75                          type1, new byte[8], null);
76  
77                      authorization = Base64.encode(type2.toByteArray());
78  
79                      response.setHeader(
80                          HttpHeaders.WWW_AUTHENTICATE, "NTLM " + authorization);
81                      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
82                      response.setContentLength(0);
83  
84                      response.flushBuffer();
85  
86                      return;
87                  }
88              }
89          }
90  
91          processFilter(NtlmPostFilter.class, request, response, filterChain);
92      }
93  
94      private static Log _log = LogFactoryUtil.getLog(NtlmPostFilter.class);
95  
96  }